fix(update): also ignore the flat-install config/credential/profile roots

The same `git stash push --include-untracked` sweep that took state.db
on a flat install (#110648) also takes every other untracked file at the
$HERMES_HOME root: config.yaml, auth.json/auth.lock, memories/,
profiles/, .credentials/, mcp-tokens/ and pairing/. Losing those on a
declined or failed restore strands the user's credentials and profile
config just as badly as losing the session store.

Extend the root-anchored block with those paths (none are tracked or
already ignored on main) and append them to the test's
FLAT_INSTALL_RUNTIME_STATE list so the existing stash invariant covers
them without a new test.
This commit is contained in:
kshitijk4poor
2026-09-14 23:16:14 +05:30
committed by kshitij
parent eef60cc1ff
commit 34a45b35e5
2 changed files with 21 additions and 3 deletions
+11 -2
View File
@@ -172,8 +172,9 @@ docs/superpowers/*
# with HERMES_INSTALL_DIR=$HERMES_HOME or by older installers): the live session
# store, its SQLite sidecars and retired-WAL capture dirs, quick snapshots, the
# legacy transcripts, the cron job store (jobs.json) and executions ledger,
# gateway lock/pid files, and cache/spill directories are Hermes-managed runtime
# state, never code changes.
# gateway lock/pid files, cache/spill directories, and the profile's own
# config/credential/memory/profile roots are Hermes-managed runtime state,
# never code changes.
# Ignore them so `hermes update`'s `git stash push --include-untracked` cannot
# sweep the live state.db/-wal into the stash and unlink it under the running
# gateway (#110648). Nested installs keep all of this under $HERMES_HOME outside
@@ -196,6 +197,14 @@ docs/superpowers/*
/gateway.pid
/hook_outputs/
/cache/
/config.yaml
/auth.json
/auth.lock
/memories/
/profiles/
/.credentials/
/mcp-tokens/
/pairing/
# Persistent dev sandbox dir (scripts/dev-sandbox.sh --persistent)
.hermes-sandbox/